As the thread title says, somehow, a person is able to access and change the /js/jslibrary.js file and place malicious code in it. Upon doing this, anyone who visits the site in Internet Explorer (Safari and Firefox appear immune to this attack) gets a popup from a domain wanting to install something malicious. In my Cubecart backend, I have noticed in the Admin Sessions area, some attempts to login followed by the attackers ip address (see screenshots). Even after replacing the jslibrar